sopcast_tv_plugin-5.4.exe

SopCast Tv Plugin 5.4 Setup Install Program

The executable sopcast_tv_plugin-5.4.exe has been detected as malware by 11 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.cool-tv.ro.
Product:
SopCast Tv Plugin 5.4 Setup Install Program

Version:
2, 0, 0, 24

MD5:
e3d72224b5c9b920f99b33cd14346e43

SHA-1:
32c8714a4527cc3c937d72c300be89264105d1e2

SHA-256:
737a1ca949b16f2b1c3f8833cc465c6fb5bb37dbe4bc34acf4450870e467c24b

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/28/2024 5:42:45 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160215-2

Dr.Web
Win32.Sector.5
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality.2.OE
10.0.0.5366

ESET NOD32
Win32/Sality.NAO virus
7.0.302.0

F-Prot
W32/Sality.AJ
4.6.5.141

F-Secure
Win32.Sality.2.OE
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.7132.0

Norman
Win32.Sality.2.OE
19.02.2016 10:08:15

VIPRE Antivirus
Threat.355724
47240

File size:
2.1 MB (2,184,178 bytes)

Product version:
2, 0, 0, 24

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\sopcast_tv_plugin-5.4.exe

File PE Metadata
Compilation timestamp:
12/17/2004 12:58:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:I7vpUqrmfi3ttfqmauWS40BmXvJJmZfFEuPuMzyz2Ka1SYVqqk:I7vpJrmfSfq908/JUZFlF9AYVzk

Entry address:
0x2E560

Entry point:
60, 01, D1, 15, 0C, 9F, E6, 11, 0F, AD, D8, 0F, BB, F7, 6A, 00, FF, 15, 1C, 1A, 43, 00, 81, E8, A8, D8, 24, 00, C0, DC, 5B, C6, C2, E9, 0F, A3, D8, E8, 00, 00, 00, 00, 51, 0F, BE, F4, 80, DC, F3, 86, D5, 5D, FF, C1, 13, F5, 8A, E2, 58, 81, C0, 00, 08, 00, 00, FF, C3, 8D, 0D, 1E, 69, 88, 2B, 0F, B3, EA, 81, C0, 47, 12, 00, 00, F2, 85, D5, 0F, CF, 81, C0, B3, 32, 00, 00, 89, E9, F2, 0F, BC, FE, 81, E8, 84, 12, 00, 00, 8B, CD, 13, CD, 0F, C1, CB, 50, 81, C0, 60, D3, 09, 00, C7, C1, CE, 59, B8, 9B, 4A, F2, 81...
 
[+]

Entropy:
7.9980  (probably packed)

Code size:
76 KB (77,824 bytes)

The file sopcast_tv_plugin-5.4.exe has been seen being distributed by the following URL.

Remove sopcast_tv_plugin-5.4.exe - Powered by Reason Core Security